Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
    Cybersecurity

    Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet

    adminBy adminMarch 15, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Botnet
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Law enforcement agencies in the United States and Europe have disrupted SocksEscort, a malicious proxy service that facilitated criminal activities.

    These proxy services enable users to hide their identity and bypass security systems. In the case of SocksEscort, it has been used for various types of cybercrime, including DDoS attacks, ransomware attacks, and the distribution of child abuse materials. 

    According to Europol and the US Justice Department, SocksEscort has been powered by compromised routers and other IoT devices, with roughly 363,000 IP addresses from 163 countries linked to the cybercrime service since 2020.

    In February 2026, just before the takedown operation was initiated, SocksEscort was supported by approximately 8,000 hacked routers, including 2,500 in the US.

    Lumen Technologies, whose Black Lotus Labs assisted the disruption efforts, said “SocksEscort maintained an average size of approximately 20,000 distinct victims weekly, with communications routed through an average of 15 command-and-control nodes.”

    SocksEscort victims

    Authorities estimate that SocksEscort customers paid a total of more than $5.7 million for the proxy service, and US Justice Department data indicates many users profited substantially from it, with some defrauding victims of hundreds of thousands or even $1 million in individual schemes.

    Europol reported that “law enforcement agencies successfully took down and seized 34 domains as well as 23 servers located in seven countries. In addition, the United States froze a total of USD 3.5 million in cryptocurrency. The infected modems used to offer the proxy service have been disconnected from the service.”

    Advertisement. Scroll to continue reading.

    The FBI on Thursday issued an alert for the AVrecon malware that has powered the SocksEscort service. The agency said the proxy service’s operators exploited known vulnerabilities in routers and IoT devices to deploy the malware and create a botnet.

    “SocksEscort uses AVrecon malware to target approximately 1,200 device models manufactured by Cisco, D-Link, Hikvision, MicroTik, Netgear, TP-Link, and Zyxel,” the FBI said. “The vast majority of observed devices infected with AVrecon malware are small-office/home-office (SOHO) routers infected using critical vulnerabilities such as Remote Code Execution (RCE) and command injection.”

    The agency has shared information on the AVrecon malware’s distribution, execution, persistence, and communication, providing indicators of compromise (IoCs) and recommendations for securing devices. 

    News of the SocksEscort takedown comes shortly after Europol, Microsoft, and cybersecurity companies announced a joint effort to take down the phishing-as-a-service platform Tycoon 2FA.

    Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown

    Related: RaccoonO365 Phishing Service Disrupted, Leader Identified

    Related: 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium

    Authorities AVrecon Botnet Disrupt Powered proxy service SocksEscort
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleUpdate Chrome Immediately to Fix This Zero-Day Exploit
    Next Article I went almost a year without actual phone service
    admin
    • Website

    Related Posts

    Betterleaks, a new open-source secrets scanner to replace Gitleaks

    March 15, 2026

    I went almost a year without actual phone service

    March 15, 2026

    Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries

    March 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    The Foilies 2026 | Electronic Frontier Foundation

    March 15, 2026

    Here’s what the Samsung Galaxy S26 Ultra’s Privacy Display does to its battery life

    March 15, 2026

    Betterleaks, a new open-source secrets scanner to replace Gitleaks

    March 15, 2026

    I went almost a year without actual phone service

    March 15, 2026
    Categories
    • Blogging (40)
    • Cybersecurity (791)
    • Privacy & Online Earning (121)
    • SEO & Digital Marketing (488)
    • Tech Tools & Mobile / Apps (968)
    • WiFi / Internet & Networking (129)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    The Foilies 2026 | Electronic Frontier Foundation

    March 15, 2026

    Here’s what the Samsung Galaxy S26 Ultra’s Privacy Display does to its battery life

    March 15, 2026

    Betterleaks, a new open-source secrets scanner to replace Gitleaks

    March 15, 2026
    Most Popular
    • The Foilies 2026 | Electronic Frontier Foundation
    • Here’s what the Samsung Galaxy S26 Ultra’s Privacy Display does to its battery life
    • Betterleaks, a new open-source secrets scanner to replace Gitleaks
    • I went almost a year without actual phone service
    • Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet
    • Update Chrome Immediately to Fix This Zero-Day Exploit
    • 4 ways to practice Python without following a tutorial
    • Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.